Re: Email Pen-testing

From: Michael Richardson (mcr_at_sandelman.ottawa.on.ca)
Date: 03/24/04

  • Next message: Lachniet, Mark: "Pen-tester's analysis of .NET security?"
    To: pen-test@securityfocus.com
    Date: Wed, 24 Mar 2004 14:42:37 -0500
    
    

    -----BEGIN PGP SIGNED MESSAGE-----

    >>>>> "Frank" == Frank Knobbe <frank@knobbe.us> writes:
        Frank> an Incident Response Exercise to test the response capabilities of a
        Frank> client. You are less concerned about getting root but instead try to
        Frank> operate stealthy or in an otherwise defined pattern, attempting to
        Frank> penetrate, but allowing others to take notes of the response
        Frank> procedures of the clients incident response team.

      Like, for instance, do the IT people even know who to call once they
    have "caught" you?

      In Canada, the responsability for "computer crime" devolved from the
    RCMP to the local police forces. Alas, the knowledge and experience did
    not get passed down. The Ottawa police, as competent as they are for
    most things, spends all their computer time tracking down child porn and
    stalkers. If you call them and say, "I'm from Corporation FOO, my
    firewall was compromised", they offer to send ... the fire department.

      So, in Ottawa at least, my conclusion is that there isn't a number
    that can be called anymore.

    - --
    ] ON HUMILITY: to err is human. To moo, bovine. | firewalls [
    ] Michael Richardson, Xelerance Corporation, Ottawa, ON |net architect[
    ] mcr@xelerance.com http://www.sandelman.ottawa.on.ca/mcr/ |device driver[
    ] panic("Just another Debian GNU/Linux using, kernel hacking, security guy"); [
      
    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1.2.2 (GNU/Linux)
    Comment: Finger me for keys

    iQCVAwUBQGHkrIqHRg3pndX9AQG4hQP/St4ihxRjdcZSYPne59pUM5//BI05iP1H
    zU7ZkqcbKvtqi6uKV08/xUxJldOeH9P7S7tM+NtfcEq0JNTYRKpj8q7IxLSgkd5g
    M+J4GM4T2k+QSBVPoG2aHAXpHrOZlSlDYWlyoqhF0gVCBf6tZoBs5aSsbgqWNa7P
    ZpEqgBErn9E=
    =Hrq3
    -----END PGP SIGNATURE-----

    ---------------------------------------------------------------------------
    You're a pen tester, but is google.com still your R&D team?
    Now you can get trustworthy commercial-grade exploits and the latest
    techniques from a world-class research group.
    www.coresecurity.com/promos/sf_ept1
    ----------------------------------------------------------------------------


  • Next message: Lachniet, Mark: "Pen-tester's analysis of .NET security?"

    Relevant Pages

    • A follow-up on Email Pen-testing
      ... > Frank> client. ... > Frank> procedures of the clients incident response team. ... >techniques from a world-class research group. ...
      (Pen-Test)
    • Re: WCF authentication and remote workstations
      ... \par Subject: Re: WCF authentication and remote workstations ... \par Frank ... For example, are you using transport layer security, ... \par> For the first one(windows authentication that let the client automatically ...
      (microsoft.public.dotnet.framework.webservices)
    • Re: TreeView 2.0 mit PopulateNodesFromClient = AJAX?
      ... "Frank Lehmann" schrieb: ... Was denkt er denn, was der Client macht, wenn man http://server/Abc.aspx ... Selbst mit CSS Adapter nicht unbedingt sinnvoll (IMHO) ... anhand übergebener Parameter die untergeordneten Elemente des Nodes ...
      (microsoft.public.de.german.entwickler.dotnet.asp)
    • Re: DB Empfehlung
      ... > Frank Seitz schrieb: ... Und an diesem Client sitzt doch ein einzelner Benutzer, ... > Darum ist es bei Desktop-DB extrem wichtig, die Abfragen ... Dipl.-Inform. Frank Seitz; http://www.fseitz.de/ ...
      (de.comp.datenbanken.misc)
    • Re: Why Google Linux will FAIL
      ... Just got a call from a client and she just hates Vista and says all her friends hate it too. ... Not that kind of lawyer but, I'll bite, what the fuck are you talking about? ... Frank is STUPID and TWISTED ... You just don't when you've had your ass kicked do you, you stupid piece of useless shit! ...
      (microsoft.public.windows.vista.general)